Junglewise Threat Intelligence

CVE-2026-9863: Fortra BoKS Manager OS command injection in client upgrade tooling

CVE-2026-9863 · Severity: high · CVSS 7.5 · Published 2026-06-15

Vendors: Fortra.

Executive brief

Fortra BoKS Manager, a centralized security administration tool, contains a vulnerability in how it handles updates for older software installations. If an administrator attempts to upgrade or patch a compromised or malicious client machine, that machine can execute unauthorized commands on the central BoKS Master server. This could lead to a total compromise of the security management infrastructure, allowing an attacker to disrupt operations or gain unauthorized access to sensitive data.

Technical details

An OS command injection vulnerability (CWE-78) exists in the Fortra BoKS Manager's client upgrade and patch tooling. The flaw is triggered during the version handling process for legacy tar-based client installations. An attacker who has compromised a legacy client can exploit this by waiting for an administrator to initiate an upgrade or patch cycle. When the BoKS Master interacts with the malicious client to process version information, it fails to properly neutralize special elements, allowing the client to inject and execute arbitrary commands on the Master server. This requires network reachability between the Master and the client and user interaction in the form of an administrator initiating the update process.

Affected products

  • Fortra BoKS Manager Legacy tar-based client installations

Timeline

  • 2026-06-15: disclosed
  • 2026-06-15: advisory

References